CVE Vulnerability Database
Search and browse 395,319 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41699 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a... |
| CVE-2026-41001 | MEDIUM | 5.3 | 0.1% | Jun 11, 2026 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da... |
| CVE-2026-41000 | LOW | 3.7 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti... |
| CVE-2026-40999 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ... |
| CVE-2026-40998 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta... |
| CVE-2026-40997 | MEDIUM | 5.3 | 0.4% | Jun 11, 2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis... |
| CVE-2026-40996 | MEDIUM | 4.8 | 0.1% | Jun 11, 2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ... |
| CVE-2026-40995 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped... |
| CVE-2026-40994 | HIGH | 8.2 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di... |
| CVE-2026-40992 | MEDIUM | 5 | 0.1% | Jun 11, 2026 | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail... |
| CVE-2026-40987 | HIGH | 7.1 | 0.2% | Jun 11, 2026 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ... |
| CVE-2026-40986 | MEDIUM | 4.8 | 0.2% | Jun 11, 2026 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not... |
| CVE-2026-10795 | HIGH | 8.1 | 3.6% | Jun 11, 2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version... |
| CVE-2026-40985 | MEDIUM | 6.4 | 0.2% | Jun 11, 2026 | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.... |
| CVE-2026-35273 | CRITICAL | 9.8 | 92.3% | Jun 11, 2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana... |
| CVE-2026-2827 | MEDIUM | 4.7 | 0.2% | Jun 11, 2026 | The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati... |
| CVE-2026-53465 | MEDIUM | 6.2 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25... |
| CVE-2026-53464 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25... |
| CVE-2026-53463 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53462 | MEDIUM | 5.9 | 0.2% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53461 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53460 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-52726 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v... |
| CVE-2026-50223 | HIGH | 8.8 | 0.7% | Jun 10, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti... |
| CVE-2026-49219 | MEDIUM | 5.5 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
